Threat Intelligence, Network Security

Report: German ISP tapped for illicit hosting infrastructure

Credit: Adobe Stock Images

GBHackers News reports that numerous threat activity enablers, including Railnet, Global-Data System IT Corporation, metaspinner net GmbH, Femo IT Solutions Ltd, and the recently sanctioned Aeza Group, have leveraged German hosting provider aurologic GmbH as a primary upstream provider.

Aside from continuously providing upstream connection to Aeza International, which has been sanctioned by the U.S. and UK, aurologic also helped support WAIcore Hosting Ltd, Tnsecurity Ltd, and Daniil Yevchenko's Altawk operation, which are Russia-linked infrastructure, according to a report from Recorded Future's Insikt Group.

Additional findings showed that aurologic was among the top 10 in terms of malicious activity concentration as of September, with the firm's attractiveness to potential threat networks attributed to its self-proclaimed neutrality and the perception of reduced enforcement risk in the EU.

Upstream network providers were urged to ensure adherence to legal obligations and ethics in operations to curb potential targeting of critical infrastructure entities.

An In-Depth Guide to Network Security

Get essential knowledge and practical strategies to fortify your network security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds